Redhat

Openstack

214 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 17.11.2024 11:15:06
  • Last modified 05.12.2024 21:15:07

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

  • EPSS 0.05%
  • Published 12.08.2024 13:38:36
  • Last modified 21.10.2024 12:15:04

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there ...

  • EPSS 0.03%
  • Published 12.08.2024 13:38:35
  • Last modified 21.11.2024 09:35:06

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there ...

  • EPSS 0.08%
  • Published 08.05.2024 09:15:09
  • Last modified 21.11.2024 09:42:49

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided...

  • EPSS 0.11%
  • Published 12.05.2023 21:15:09
  • Last modified 24.01.2025 16:15:31

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. ...

  • EPSS 0.01%
  • Published 23.03.2023 21:15:19
  • Last modified 21.11.2024 07:18:55

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover th...

  • EPSS 0.01%
  • Published 23.03.2023 21:15:18
  • Last modified 21.11.2024 07:18:49

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover th...

  • EPSS 0.09%
  • Published 06.03.2023 23:15:11
  • Last modified 06.03.2025 20:15:37

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

  • EPSS 0.03%
  • Published 18.01.2023 17:15:10
  • Last modified 03.04.2025 20:15:17

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

Exploit
  • EPSS 0.11%
  • Published 21.12.2022 11:15:10
  • Last modified 21.11.2024 07:15:42

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.